diff --git a/misc/tools.func b/misc/tools.func index 6bee4fbd0..bacce96df 100644 --- a/misc/tools.func +++ b/misc/tools.func @@ -3058,69 +3058,69 @@ setup_mariadb() { # - Exports variables for use in calling script # # Usage: -# DB_NAME="myapp_db" DB_USER="myapp_user" setup_mariadb_db -# DB_NAME="domain_monitor" DB_USER="domainmonitor" setup_mariadb_db -# DB_NAME="myapp" DB_USER="myapp" DB_EXTRA_GRANTS="GRANT SELECT ON \`mysql\`.\`time_zone_name\`" setup_mariadb_db -# DB_NAME="ghostfolio" DB_USER="ghostfolio" DB_SQL_MODE="" setup_mariadb_db +# MARIADB_DB_NAME="myapp_db" MARIADB_DB_USER="myapp_user" setup_mariadb_db +# MARIADB_DB_NAME="domain_monitor" MARIADB_DB_USER="domainmonitor" setup_mariadb_db +# MARIADB_DB_NAME="myapp" MARIADB_DB_USER="myapp" MARIADB_DB_EXTRA_GRANTS="GRANT SELECT ON \`mysql\`.\`time_zone_name\`" setup_mariadb_db +# MARIADB_DB_NAME="ghostfolio" MARIADB_DB_USER="ghostfolio" MARIADB_DB_SQL_MODE="" setup_mariadb_db # # Variables: -# DB_NAME - Database name (required) -# DB_USER - Database user (required) -# DB_PASS - User password (optional, auto-generated if empty) -# DB_EXTRA_GRANTS - Comma-separated GRANT statements (optional) -# Example: "GRANT SELECT ON \`mysql\`.\`time_zone_name\`" -# DB_SQL_MODE - Optional global sql_mode override (e.g. "", "STRICT_TRANS_TABLES") -# DB_CREDS_FILE - Credentials file path (optional, default: ~/mariadb_${DB_NAME}.creds) +# MARIADB_DB_NAME - Database name (required) +# MARIADB_DB_USER - Database user (required) +# MARIADB_DB_PASS - User password (optional, auto-generated if empty) +# MARIADB_DB_EXTRA_GRANTS - Comma-separated GRANT statements (optional) +# Example: "GRANT SELECT ON \`mysql\`.\`time_zone_name\`" +# MARIADB_DB_SQL_MODE - Optional global sql_mode override (e.g. "", "STRICT_TRANS_TABLES") +# MARIADB_DB_CREDS_FILE - Credentials file path (optional, default: ~/${APPLICATION}.creds) # # Exports: # MARIADB_DB_NAME, MARIADB_DB_USER, MARIADB_DB_PASS # ------------------------------------------------------------------------------ function setup_mariadb_db() { - if [[ -z "${DB_NAME:-}" || -z "${DB_USER:-}" ]]; then - msg_error "DB_NAME and DB_USER must be set before calling setup_mariadb_db" + if [[ -z "${MARIADB_DB_NAME:-}" || -z "${MARIADB_DB_USER:-}" ]]; then + msg_error "MARIADB_DB_NAME and MARIADB_DB_USER must be set before calling setup_mariadb_db" return 1 fi - if [[ -z "${DB_PASS:-}" ]]; then - DB_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13) + if [[ -z "${MARIADB_DB_PASS:-}" ]]; then + MARIADB_DB_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13) fi msg_info "Setting up MariaDB Database" - $STD mariadb -u root -e "CREATE DATABASE \`$DB_NAME\` CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;" - $STD mariadb -u root -e "CREATE USER '$DB_USER'@'localhost' IDENTIFIED BY '$DB_PASS';" - $STD mariadb -u root -e "GRANT ALL ON \`$DB_NAME\`.* TO '$DB_USER'@'localhost';" + $STD mariadb -u root -e "CREATE DATABASE \`$MARIADB_DB_NAME\` CHARACTER SET utf8mb4 COLLATE utf8mb4_unicode_ci;" + $STD mariadb -u root -e "CREATE USER '$MARIADB_DB_USER'@'localhost' IDENTIFIED BY '$MARIADB_DB_PASS';" + $STD mariadb -u root -e "GRANT ALL ON \`$MARIADB_DB_NAME\`.* TO '$MARIADB_DB_USER'@'localhost';" # Optional extra grants - if [[ -n "${DB_EXTRA_GRANTS:-}" ]]; then - IFS=',' read -ra G_LIST <<<"${DB_EXTRA_GRANTS:-}" + if [[ -n "${MARIADB_DB_EXTRA_GRANTS:-}" ]]; then + IFS=',' read -ra G_LIST <<<"${MARIADB_DB_EXTRA_GRANTS:-}" for g in "${G_LIST[@]}"; do g=$(echo "$g" | xargs) - $STD mariadb -u root -e "$g TO '$DB_USER'@'localhost';" + $STD mariadb -u root -e "$g TO '$MARIADB_DB_USER'@'localhost';" done fi # Optional sql_mode override - if [[ -n "${DB_SQL_MODE:-}" ]]; then - $STD mariadb -u root -e "SET GLOBAL sql_mode='${DB_SQL_MODE:-}';" + if [[ -n "${MARIADB_DB_SQL_MODE:-}" ]]; then + $STD mariadb -u root -e "SET GLOBAL sql_mode='${MARIADB_DB_SQL_MODE:-}';" fi $STD mariadb -u root -e "FLUSH PRIVILEGES;" - local CREDS_FILE="${DB_CREDS_FILE:-${HOME}/${APPLICATION}.creds}" + local CREDS_FILE="${MARIADB_DB_CREDS_FILE:-${HOME}/${APPLICATION}.creds}" { echo "MariaDB Credentials" - echo "Database: $DB_NAME" - echo "User: $DB_USER" - echo "Password: $DB_PASS" + echo "Database: $MARIADB_DB_NAME" + echo "User: $MARIADB_DB_USER" + echo "Password: $MARIADB_DB_PASS" } >>"$CREDS_FILE" msg_ok "Set up MariaDB Database" - export MARIADB_DB_NAME="$DB_NAME" - export MARIADB_DB_USER="$DB_USER" - export MARIADB_DB_PASS="$DB_PASS" + export MARIADB_DB_NAME + export MARIADB_DB_USER + export MARIADB_DB_PASS } # ------------------------------------------------------------------------------ @@ -3894,20 +3894,20 @@ function setup_postgresql() { # - Exports variables for use in calling script # # Usage: -# DB_NAME="myapp_db" DB_USER="myapp_user" setup_postgresql_db -# DB_NAME="immich" DB_USER="immich" DB_EXTENSIONS="pgvector" setup_postgresql_db -# DB_NAME="ghostfolio" DB_USER="ghostfolio" DB_GRANT_SUPERUSER="true" setup_postgresql_db -# DB_NAME="adventurelog" DB_USER="adventurelog" DB_EXTENSIONS="postgis" setup_postgresql_db +# PG_DB_NAME="myapp_db" PG_DB_USER="myapp_user" setup_postgresql_db +# PG_DB_NAME="immich" PG_DB_USER="immich" PG_DB_EXTENSIONS="pgvector" setup_postgresql_db +# PG_DB_NAME="ghostfolio" PG_DB_USER="ghostfolio" PG_DB_GRANT_SUPERUSER="true" setup_postgresql_db +# PG_DB_NAME="adventurelog" PG_DB_USER="adventurelog" PG_DB_EXTENSIONS="postgis" setup_postgresql_db # # Variables: -# DB_NAME - Database name (required) -# DB_USER - Database user (required) -# DB_PASS - Database password (optional, auto-generated if empty) -# DB_EXTENSIONS - Comma-separated list of extensions (optional, e.g. "postgis,pgvector") -# DB_GRANT_SUPERUSER - Grant SUPERUSER privilege (optional, "true" to enable, security risk!) -# DB_SCHEMA_PERMS - Grant schema-level permissions (optional, "true" to enable) -# DB_SKIP_ALTER_ROLE - Skip ALTER ROLE settings (optional, "true" to skip) -# DB_CREDS_FILE - Credentials file path (optional, default: ~/pg_${DB_NAME}.creds) +# PG_DB_NAME - Database name (required) +# PG_DB_USER - Database user (required) +# PG_DB_PASS - Database password (optional, auto-generated if empty) +# PG_DB_EXTENSIONS - Comma-separated list of extensions (optional, e.g. "postgis,pgvector") +# PG_DB_GRANT_SUPERUSER - Grant SUPERUSER privilege (optional, "true" to enable, security risk!) +# PG_DB_SCHEMA_PERMS - Grant schema-level permissions (optional, "true" to enable) +# PG_DB_SKIP_ALTER_ROLE - Skip ALTER ROLE settings (optional, "true" to skip) +# PG_DB_CREDS_FILE - Credentials file path (optional, default: ~/${APPLICATION}.creds) # # Exports: # PG_DB_NAME, PG_DB_USER, PG_DB_PASS - For use in calling script @@ -3915,68 +3915,68 @@ function setup_postgresql() { function setup_postgresql_db() { # Validation - if [[ -z "${DB_NAME:-}" || -z "${DB_USER:-}" ]]; then - msg_error "DB_NAME and DB_USER must be set before calling setup_postgresql_db" + if [[ -z "${PG_DB_NAME:-}" || -z "${PG_DB_USER:-}" ]]; then + msg_error "PG_DB_NAME and PG_DB_USER must be set before calling setup_postgresql_db" return 1 fi # Generate password if not provided - if [[ -z "${DB_PASS:-}" ]]; then - DB_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13) + if [[ -z "${PG_DB_PASS:-}" ]]; then + PG_DB_PASS=$(openssl rand -base64 18 | tr -dc 'a-zA-Z0-9' | head -c13) fi msg_info "Setting up PostgreSQL Database" - $STD sudo -u postgres psql -c "CREATE ROLE $DB_USER WITH LOGIN PASSWORD '$DB_PASS';" - $STD sudo -u postgres psql -c "CREATE DATABASE $DB_NAME WITH OWNER $DB_USER ENCODING 'UTF8' TEMPLATE template0;" + $STD sudo -u postgres psql -c "CREATE ROLE $PG_DB_USER WITH LOGIN PASSWORD '$PG_DB_PASS';" + $STD sudo -u postgres psql -c "CREATE DATABASE $PG_DB_NAME WITH OWNER $PG_DB_USER ENCODING 'UTF8' TEMPLATE template0;" # Install extensions (comma-separated) - if [[ -n "${DB_EXTENSIONS:-}" ]]; then - IFS=',' read -ra EXT_LIST <<<"${DB_EXTENSIONS:-}" + if [[ -n "${PG_DB_EXTENSIONS:-}" ]]; then + IFS=',' read -ra EXT_LIST <<<"${PG_DB_EXTENSIONS:-}" for ext in "${EXT_LIST[@]}"; do ext=$(echo "$ext" | xargs) # Trim whitespace - $STD sudo -u postgres psql -d "$DB_NAME" -c "CREATE EXTENSION IF NOT EXISTS $ext;" + $STD sudo -u postgres psql -d "$PG_DB_NAME" -c "CREATE EXTENSION IF NOT EXISTS $ext;" done fi # ALTER ROLE settings for Django/Rails compatibility (unless skipped) - if [[ "${DB_SKIP_ALTER_ROLE:-}" != "true" ]]; then - $STD sudo -u postgres psql -c "ALTER ROLE $DB_USER SET client_encoding TO 'utf8';" - $STD sudo -u postgres psql -c "ALTER ROLE $DB_USER SET default_transaction_isolation TO 'read committed';" - $STD sudo -u postgres psql -c "ALTER ROLE $DB_USER SET timezone TO 'UTC';" + if [[ "${PG_DB_SKIP_ALTER_ROLE:-}" != "true" ]]; then + $STD sudo -u postgres psql -c "ALTER ROLE $PG_DB_USER SET client_encoding TO 'utf8';" + $STD sudo -u postgres psql -c "ALTER ROLE $PG_DB_USER SET default_transaction_isolation TO 'read committed';" + $STD sudo -u postgres psql -c "ALTER ROLE $PG_DB_USER SET timezone TO 'UTC';" fi # Schema permissions (if requested) - if [[ "${DB_SCHEMA_PERMS:-}" == "true" ]]; then - $STD sudo -u postgres psql -c "GRANT ALL PRIVILEGES ON DATABASE $DB_NAME TO $DB_USER;" - $STD sudo -u postgres psql -c "ALTER USER $DB_USER CREATEDB;" - $STD sudo -u postgres psql -d "$DB_NAME" -c "GRANT ALL ON SCHEMA public TO $DB_USER;" - $STD sudo -u postgres psql -d "$DB_NAME" -c "GRANT CREATE ON SCHEMA public TO $DB_USER;" - $STD sudo -u postgres psql -d "$DB_NAME" -c "ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON TABLES TO $DB_USER;" - $STD sudo -u postgres psql -d "$DB_NAME" -c "ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON SEQUENCES TO $DB_USER;" + if [[ "${PG_DB_SCHEMA_PERMS:-}" == "true" ]]; then + $STD sudo -u postgres psql -c "GRANT ALL PRIVILEGES ON DATABASE $PG_DB_NAME TO $PG_DB_USER;" + $STD sudo -u postgres psql -c "ALTER USER $PG_DB_USER CREATEDB;" + $STD sudo -u postgres psql -d "$PG_DB_NAME" -c "GRANT ALL ON SCHEMA public TO $PG_DB_USER;" + $STD sudo -u postgres psql -d "$PG_DB_NAME" -c "GRANT CREATE ON SCHEMA public TO $PG_DB_USER;" + $STD sudo -u postgres psql -d "$PG_DB_NAME" -c "ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON TABLES TO $PG_DB_USER;" + $STD sudo -u postgres psql -d "$PG_DB_NAME" -c "ALTER DEFAULT PRIVILEGES IN SCHEMA public GRANT ALL ON SEQUENCES TO $PG_DB_USER;" fi # Superuser grant (if requested - WARNING!) - if [[ "${DB_GRANT_SUPERUSER:-}" == "true" ]]; then + if [[ "${PG_DB_GRANT_SUPERUSER:-}" == "true" ]]; then msg_warn "Granting SUPERUSER privilege (security risk!)" - $STD sudo -u postgres psql -c "GRANT ALL PRIVILEGES ON DATABASE $DB_NAME to $DB_USER;" - $STD sudo -u postgres psql -c "ALTER USER $DB_USER WITH SUPERUSER;" + $STD sudo -u postgres psql -c "GRANT ALL PRIVILEGES ON DATABASE $PG_DB_NAME to $PG_DB_USER;" + $STD sudo -u postgres psql -c "ALTER USER $PG_DB_USER WITH SUPERUSER;" fi # Save credentials - local CREDS_FILE="${DB_CREDS_FILE:-${HOME}/${APPLICATION}.creds}" + local CREDS_FILE="${PG_DB_CREDS_FILE:-${HOME}/${APPLICATION}.creds}" { echo "PostgreSQL Credentials" - echo "Database: $DB_NAME" - echo "User: $DB_USER" - echo "Password: $DB_PASS" + echo "Database: $PG_DB_NAME" + echo "User: $PG_DB_USER" + echo "Password: $PG_DB_PASS" } >>"$CREDS_FILE" msg_ok "Set up PostgreSQL Database" # Export for use in calling script - export PG_DB_NAME="$DB_NAME" - export PG_DB_USER="$DB_USER" - export PG_DB_PASS="$DB_PASS" + export PG_DB_NAME + export PG_DB_USER + export PG_DB_PASS } # ------------------------------------------------------------------------------